Live data from Hacker News

Internet Archive: Security breach alert

theverge.com

481–490 of 648 posts

Re: Internet Archive: Security breach alert

#483
post #396
post #385

Earlier quoted context omitted.

Yes, without exception. I want to know who is leaking/selling my address, and usually stop doing business with those who do. It also makes filtering really easy. People sometimes have strange reactions when I verbally give them an email address with their company name in it, especially when I'm a new customer. All you need is a domain and an email provider that allows catch-all addresses, both of which are easy and c…

I do the same but use initials and random chars so hackers or employees can’t assume my email addresses for other sites/services. e.g.: hn_t47fb@my.domain

I also use @my.other.domain for websites, so my human contacts won't assume it is me if they see it.

Re: Internet Archive: Security breach alert

#484

Earlier quoted context omitted.

“I went to the site to jerk off (to an adult scenario, to be clear) and noticed that it looked like it [the Muah.ai website] was put together pretty poorly,” the hacker told 404 Media. “It's basically a handful of open-source projects duct-taped together. I started poking around and found some vulnerabilities relatively quickly. At the start it was mostly just curiosity but I decided to contact you once I saw what wa…

Not sure if you're being sarcastic or not, but pentesting is not a particularly evil activity — and you often have to look at data to see if you actually found something. What is evil is the way that he's ensured that the predators in the dataset will never face any consequences by making the data available to HaveIBeenPwned, making it trivial for predators to protect themselves (the method through which this is poss…

Did you miss the joke? Parent poster means penetration as in penetrative sex

Re: Internet Archive: Security breach alert

#485
post #164

Earlier quoted context omitted.

Friendly reminder to generate a unique password for every account you create so database leaks like this one don't bother you (besides on the site they're used).

MFA

... is not something your should rely on.

Re: Internet Archive: Security breach alert

#486

Earlier quoted context omitted.

This raises an interesting question: should email addresses be private? Addresses of buildings aren't private, and they're somewhat analogous as with many computing concepts. (Aside: Before spam filters were quite good, it was typical to avoid scraping of addresses by mild obfuscation, but I think those days are gone, and this is distinct from privacy anyway.) If someone wants to upload and never be found out, then t…

There is software which is intended to e.g. locate the GitHub profiles of people working at companies, then scrape all public repositories they've contributed to for their email address and the emails of their coworkers - to enable targeted advertising to those individuals. Very common in enterprise sales. With ChatGPT, this can be extended to create emails that look very personal - as if someone has followed all of…

This was a problem already before the generative AI era, it just got less expensive. The only way to reduce it is to have two work addresses: one that you rarely check and is exposed to the public, listed on your profile etc., and the real internal one just to get the work done.

Re: Internet Archive: Security breach alert

#487

A pulled an old friends website down from Internet Archive. He's moved on the next stage, but I was glad I was able to put his site back up. It'll be a shame if IA goes down permanently, but we need a decentralized solution anyway. Having a single mega organization in charge of our collective heritage isn't a good idea.

Agreed, especially an organziation that has already shown to not always be impartial.

Re: Internet Archive: Security breach alert

#489

I have had an IA account for a number of years, with a gmail address. Nine months ago, I changed the email address to a masked address using my own domain. Now I find that my gmail address was still stored, and was involved in the breach. Why? I get that they might store change history, but why? BTW, for the current account details, I changed the password to another random string generated by my password manager, and…

It's also possible that the breach was earlier or going on for longer than reported.

Re: Internet Archive: Security breach alert

#490

Earlier quoted context omitted.

“I went to the site to jerk off (to an adult scenario, to be clear) and noticed that it looked like it [the Muah.ai website] was put together pretty poorly,” the hacker told 404 Media. “It's basically a handful of open-source projects duct-taped together. I started poking around and found some vulnerabilities relatively quickly. At the start it was mostly just curiosity but I decided to contact you once I saw what wa…

True penetration testing.

Well, only success with one kind.
Post reply on HN